Skip to main content
Emerging ThreatsMalware & Ransomware

US Bank Probes LockBit Ransomware Claim, Faces Data Leak Deadline

Bank lobby with blurred employee in background, flooded with natural daylight through large window or glass door.

"We're aware of claims regarding a potential cybersecurity incident," Lee Henderson, US Bank VP of public affairs, said in an emailed statement to The Register.

US Bank response: investigation, but few specifics

US Bank has publicly acknowledged it is investigating LockBit's claim that the ransomware crew breached the institution and stole data, but has declined to answer specific questions about the allegation. The bank would not say whether it has communicated with the extortionists or disclose the size of any ransom demand. In its statement, the bank asserted that "at this time, there is no indication that our internal systems are impacted and no evidence of unauthorized access to our network." The bank added that it "takes the security and privacy of our clients' and employees' information very seriously" and that it is continuing to investigate and "closely monitor these claims."

LockBit's claim and the pay‑or‑leak ultimatum

LockBit added US Bank to its leak site late Wednesday night and gave the bank 14 days to pay a ransom demand or face public exposure of allegedly stolen files. The criminals set a deadline of September 3 for the data dump unless the bank meets their demand. The leak-site post did not specify how many files were allegedly taken or what those files contained. The Register reported that the bank declined to answer questions about communications with the extortionists or the ransom amount.

Why payment does not guarantee deletion: LockBit's operational history

Even when victims pay, there is no guarantee that LockBit or its iterations will delete stolen data. When law enforcement dismantled an earlier iteration of LockBit in 2024, investigators found evidence that the group retained victim data after victims had paid extortion demands. International law enforcement action in February 2024 seized servers, domain infrastructure, and decryption keys in an effort to dismantle the group; in May 2024 authorities publicly identified LockBitSupp's true identity. The source notes that Dmitry Yuryevich Khoroshev, a Russian national tied to that outing, remains at large. Despite the 2024 takedown, LockBit reemerged in September 2025 with a new variant called LockBit 5.0, and it continues to operate public leak sites and extortion campaigns.

Context inside US Bank: recent third‑party incidents and customer notices

LockBit's claim follows a string of third‑party incidents that have affected US Bank customers' data in recent years. The bank reportedly learned on May 7 about a third‑party incident that reached it through vendor Fidelity National Information Services; in June, US Bank began notifying 537 customers — all Massachusetts residents — that names, mailing addresses, and credit card numbers may have been stolen. The bank said customers' Social Security numbers, online banking credentials, and account balances were not accessed in that incident. Separately, a larger 2022 incident tied to a different vendor "accidentally shared" a file containing personal information associated with closed US Bank credit card accounts affecting roughly 11,000 customers; that file included names, addresses, Social Security numbers, dates of birth, closed account numbers, and outstanding balances. At least one law firm has said it is considering a class‑action lawsuit against US Bank National Association on behalf of a small group of customers whose credit card information may have been exposed in the more recent vendor‑related incident.

What this means for technologists, affected customers, and legal counsel

  • Technologists and security teams: the case underscores the continued operational presence of LockBit variants after law‑enforcement takedowns and the limits of paying ransoms to secure deletion — investigators in 2024 found retention of victim data even after payment.
  • Affected customers and the public: customers tied to prior vendor incidents received notices in June (537 Massachusetts residents) and some 11,000 customers were affected by a separate 2022 vendor error; those groups were told which data elements were at risk and which were not.
  • Legal counsel and firms considering litigation: at least one law firm is weighing a class action against US Bank National Association related to the vendor‑linked exposure of credit card information, a development that follows the bank's public disclosures and customer notifications.

The claim now hangs on investigation results and choices US Bank will make under a 14‑day clock that culminates on September 3. The bank says it sees no evidence of unauthorized access to its network so far, but has not answered whether it has engaged with the extortionists or intends to pay. Those facts — and whether files actually exist to be leaked — remain the central open questions as the deadline approaches.

Original story at The Register